Splunk Search

How to view tools.csv file?

jamie1
Path Finder

Hi There,

I am currently looking at a search within Splunk Security Essentials (Concentration of Attacker Tools by Filename).

The search mentions a file named "tools.csv", which I assume is a list of the attacker tools mentioned in the title of the search. 

Is there any way that I can access the contents of the CSV file? Purely because I want to see which tools are listed.

Any help would be appreciated,

Jamie

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You could try

| inputlookup tools.csv

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could try

| inputlookup tools.csv
0 Karma

jamie1
Path Finder

Hi There,

That worked 🙂

Cheers,

Jamie

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...